Skip to content

Services/ISO / NIS2 / NIST

ISO 27001, NIS2 & NIST

The paperwork only holds if the technical work underneath it is real.

Enquire about this service
Interior of Lloyd's of London in the City

ISO/IEC 27001

Consultants are qualified to perform ISO 27001 audits, gap analysis and certification support. We do not sell a binder of policies. We help you build an information security management system that matches how the organisation actually works — then produce the evidence a certification body will accept.

Where the control set is the actual requirement, we work to ISO/IEC 27002, and to ISO/IEC 27701 when privacy management sits beside the ISMS.

NIS2

The EU Network and Information Security Directive (NIS2) raises the bar for essential and important entities, and for their suppliers. We map current technical and organisational measures against the directive, identify gaps, and help you close them — including the incident-reporting and supply-chain duties that catch teams off guard.

UK organisations selling into the EU, and Portuguese operations in scope, are a typical fit.

NIST CSF 2.0 and the 800-series

For organisations that need to speak NIST — Cybersecurity Framework 2.0, SP 800-53, SP 800-171 — we translate the control families into tests, architecture changes and evidence, rather than a spreadsheet of 'partially implemented'.

Other regimes we cover

UK Cyber Essentials and Cyber Essentials Plus — the baseline many insurers and public-sector buyers now expect.

IEC 62443 for industrial control and OT. We already research SCADA and ICS software; the standard work sits on that technical base.

SOC 2 for product companies selling into the US. PCI DSS where card data is in scope.

Why a technical firm

Most gap analyses are written by people who have never exploited a real system. Ours are not. The same consultants who find 0-days can tell you whether a control would actually stop an attacker — and what to put in its place if it would not.

Contact us today to find out how we can help you.

Short engagements, senior consultants, and work we actually sign our names to.